Shreya Patni
Shreya Patni

Reputation: 62

Forward syslog stream using Splunk Forwarder

How can I forward syslog stream using Splunk Universal Forwarder?

I have a centos7 system, and I want to forward the stream eg. localx without having to write it to disk. Currently, I am only able to forward if I write the stream to disk and configure the forwarder to consume the file.

Upvotes: 0

Views: 482

Answers (1)

RichG
RichG

Reputation: 9976

If you insist on using the UF then writing to disk is the way.

If you want to avoid writing to disk and are open to a non-UF solution, then consider Splunk Connect for Syslog (SC4S). It's a docker app that receives syslog streams and sends them to Splunk HEC inputs. See https://splunkbase.splunk.com/app/4740/ for more information.

Upvotes: 2

Related Questions